<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ep-patent-document PUBLIC "-//EPO//EP PATENT DOCUMENT 1.1//EN" "ep-patent-document-v1-1.dtd">
<ep-patent-document id="EP01102150B1" file="01102150.xml" lang="en" country="EP" doc-number="1122932" kind="B1" date-publ="20060809" status="n" dtd-version="ep-patent-document-v1-1">
<SDOBI lang="en"><B000><eptags><B001EP>ATBECHDEDKESFRGBGRITLILUNLSEMCPTIE......FI....CY..TR............................</B001EP><B005EP>J</B005EP><B007EP>DIM360 (Ver 1.5  21 Nov 2005) -  2100000/0</B007EP></eptags></B000><B100><B110>1122932</B110><B120><B121>EUROPEAN PATENT SPECIFICATION</B121></B120><B130>B1</B130><B140><date>20060809</date></B140><B190>EP</B190></B100><B200><B210>01102150.8</B210><B220><date>20010201</date></B220><B240><B241><date>20040301</date></B241><B242><date>20040408</date></B242></B240><B250>en</B250><B251EP>en</B251EP><B260>en</B260></B200><B300><B310>498093</B310><B320><date>20000204</date></B320><B330><ctry>US</ctry></B330></B300><B400><B405><date>20060809</date><bnum>200632</bnum></B405><B430><date>20010808</date><bnum>200132</bnum></B430><B450><date>20060809</date><bnum>200632</bnum></B450><B452EP><date>20060220</date></B452EP></B400><B500><B510EP><classification-ipcr sequence="1"><text>H04L  29/06        20060101AFI20010517BHEP        </text></classification-ipcr><classification-ipcr sequence="2"><text>G06F   1/00        20060101ALI20030814BHEP        </text></classification-ipcr></B510EP><B540><B541>de</B541><B542>Schutz von Computernetzen gegen böswillige Inhalte</B542><B541>en</B541><B542>Protection of computer networks against malicious content</B542><B541>fr</B541><B542>Protection de réseaux d'ordinateurs contre des contenus malintentionnés</B542></B540><B560><B561><text>WO-A-00/00879</text></B561><B561><text>WO-A-97/39399</text></B561><B561><text>US-A- 6 088 803</text></B561></B560><B590><B598>1A</B598></B590></B500><B700><B720><B721><snm>Margalit, Dany</snm><adr><str>10 Kiriaty Street</str><city>Ramat Gan 52223</city><ctry>IL</ctry></adr></B721><B721><snm>Gruper, Shimon</snm><adr><str>17 Hanoter Street</str><city>Kiryat Haim 26307</city><ctry>IL</ctry></adr></B721></B720><B730><B731><snm>Aladdin Knowledge Systems Ltd.</snm><iid>02870680</iid><irf>1994/GM/fh</irf><adr><str>15 Beit Oved Street</str><city>Tel Aviv 67211</city><ctry>IL</ctry></adr></B731></B730><B740><B741><snm>Modiano, Micaela Nadia</snm><iid>00097641</iid><adr><str>Modiano, Josif, Pisanty &amp; Staub Ltd., 
Baaderstrasse 3</str><city>80469 München</city><ctry>DE</ctry></adr></B741></B740></B700><B800><B840><ctry>AT</ctry><ctry>BE</ctry><ctry>CH</ctry><ctry>CY</ctry><ctry>DE</ctry><ctry>DK</ctry><ctry>ES</ctry><ctry>FI</ctry><ctry>FR</ctry><ctry>GB</ctry><ctry>GR</ctry><ctry>IE</ctry><ctry>IT</ctry><ctry>LI</ctry><ctry>LU</ctry><ctry>MC</ctry><ctry>NL</ctry><ctry>PT</ctry><ctry>SE</ctry><ctry>TR</ctry></B840><B880><date>20031008</date><bnum>200341</bnum></B880></B800></SDOBI><!-- EPO <DP n="1"> -->
<description id="desc" lang="en">
<heading id="h0001">FIELD OF THE INVENTION</heading>
<p id="p0001" num="0001">The present invention relates to computer network communications generally and more particularly to apparatus and methods for providing security in computer network communications.</p>
<heading id="h0002">BACKGROUND OF THE INVENTION</heading>
<p id="p0002" num="0002">There exist a large number of U.S. Patents which deal with security in computer network communications. The following U.S. Patents and the references cited therein are believed to represent the state of the art: 5,951,698; 5,918,008; 5,907,834; 5,892,904; 5,889,943; 5,881,151; 5,859,966; 5,854,916; 5,842,002; 5,832,208; 5,826,012; 5,822,517; 5,809,138; 5,802,277; 5,748,940; 5,684,875; 5,679,525; 5,675,711; 5,666,411; 5,657,473; 5,649,095; 5,623,600; 5,613,002; 5,537,540; 5,511,184; 5,111,163; 5,502,815; 5,485,575; 5,473,769; 5,452,442; 5,398,196; 5,359,659; 5,319,776.</p>
<p id="p0003" num="0003">Security in computer network communications deals with two general types of malicious content which may be communicated over a network to a computer: viruses and<!-- EPO <DP n="2"> --> vandals. Viruses may be classified into a number of categories, such as file infectors, file system viruses, macro viruses and system/boot record infectors.</p>
<p id="p0004" num="0004">Vandals are distinguished from viruses in that whereas viruses require a user to execute a program in order to cause damage, vandals are auto-executable Internet applications and may cause immediate damage. Currently the following types of vandals are known: Java applets, ActiveX objects, scripts and cookies. Vandals may bide in various types of communicated content, including Email, web content, legitimate sites and file downloads.</p>
<p id="p0005" num="0005">It is known to employ proxy servers to detect and prevent receipt of malicious content by a computer. Use of proxy servers for this type of application is described inter alia in the aforesaid U.S. Patents 5,951,698; 5,889,943 &amp; 5,623,600. The use of proxy servers for this purpose has a number of disadvantages including non-real time operation, generation of network bottlenecks, requiring special configuration of each desktop and relative ease of bypass by a user.</p>
<p id="p0006" num="0006">WO 00/00879 discloses a Virtual Private Network (VPN) in which computers are connected to access filters that provide access checking at IP-level and protocol. The access filters comprise proxies that, efter having checked and confurned that access is to be allowed, check all data entering the VPN and transfer such data to the clients and to a temporary file for virus checking, preventing the last portion of data from being sent to the clients until virus checking is complete.<br/>
WO 97/39399 discloses an apparatus for detecting and eliminating viruses which may be introduoed by messages through a postal node of a network e-mail system, in which postal node is polled for unscanned messages, which are downloaded and checked for viruses into a memory of the node.</p>
<heading id="h0003">SUMMARY OF THE INVENTION</heading>
<p id="p0007" num="0007">The present invention seeks to provide apparatus and a method for protection of computers against malicious content generally in real time and without requiring the use of a proxy server. The apparatus and the method according to the invention are defined in the appented claims.</p>
<p id="p0008" num="0008">There is provided in accordance with a preferred embodiment of the present invention a gateway including an input for receiving communications packets, an output for outputting communications packets generally in real time with respect to receipt thereof, a policy manager determining criteria for collection and inspection of a collection of packets and a packet collection agent receiving packets from the input in accordance with criteria established by the policy manager and including a content inspector inspecting the collection of packets in accordance with criteria established by the policy manager and being operative to prevent supply of at least one packet of a collection of packets to the output when the collection of packets includes undesirable content in accordance with the criteria<!-- EPO <DP n="3"> --><!-- EPO <DP n="4"> --> established by the policy manager.</p>
<p id="p0009" num="0009">There is also provided in accordance with a preferred embodiment of the present invention a method for protecting a computer from malicious content comprising the steps of:
<ul id="ul0001" list-style="none" compact="compact">
<li>determining criteria for collection and inspection of a collection of packets;</li>
<li>receiving packets from among the collection of packets in accordance with the criteria;</li>
<li>inspecting the packets in accordance with the criteria;</li>
<li>preventing output of at least one packet but not all packets of a collection of packets when the collection of packets includes undesirable content in accordance with the criteria; and</li>
<li>outputting packets other than the at least one packet generally in real time with respect to receipt thereof;</li>
</ul></p>
<p id="p0010" num="0010">In accordance with a preferred embodiment of the present invention, the at least one packet is the last packet of a file.</p>
<heading id="h0004">BRIEF DESCRIPTION OF THE DRAWINGS</heading>
<p id="p0011" num="0011">The present invention will be understood and appreciated more fully from the following detailed description, taken in conjunction with the drawings in which:
<ul id="ul0002" list-style="none" compact="compact">
<li>Fig. 1A is a simplified block diagram illustration of implementation of the invention in a firewall-type configuration for checking incoming Internet but not intranet traffic;</li>
<li>Fig. 1B is a simplified block diagram illustration of implementation of the invention for checking all incoming communications;</li>
<li>Fig. 2 is a simplified block diagram illustration of the use of multiple content inspectors by a single packet collection agent; and<!-- EPO <DP n="5"> --></li>
<li>Fig. 3 is a simplified flow chart illustrating operation of a packet collection agent in accordance with a preferred embodiment of the present invention.</li>
</ul></p>
<heading id="h0005">DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS</heading>
<p id="p0012" num="0012">The present invention seeks to provide protection of a computer against malicious content without requiring the use of a proxy server.</p>
<p id="p0013" num="0013">Reference is now made to Fig. 1A, which is a simplified block diagram illustration of implementation of the invention in a firewall-type configuration for checking incoming Internet but not intranet traffic. As seen in Fig. 1A, there is provided a typical computer 10 in which resides conventional TCP/IP routing software 12. Computer 10 is typically connected to a network 13.</p>
<p id="p0014" num="0014">In accordance with a preferred embodiment of the present invention a packet collection agent (PCA) 14 is interposed between a network interface card (NIC) 16 which receives Internet traffic and the TCP/IP routing software 12. In this embodiment, a separate NIC 18 handles intranet traffic and does not have a PCA interfaced between it and the TCP/IP routing software 12.</p>
<p id="p0015" num="0015">In accordance with a preferred embodiment of the present invention, the PCA 14 interfaces with policy manager software 20, which determines collection criteria, i.e. which types of packets of which types of files are collected, and inspection criteria, i.e. which types of content in a file are not allowed to pass to or from network 13.</p>
<p id="p0016" num="0016">Based on the criteria established by the policy manager software 20, the PCA 14 operates content inspector software 22, which inspects the packets of a file which fits the criteria for collection and inspection. The content inspector software 22 operates based on criteria established by the policy manager software 20 and reports its inspection findings to the PCA 14. Alternatively, policy manager software 20 may be obviated. In such a case, the PCA 14 and the content inspector software are each programmed with suitable criteria.<!-- EPO <DP n="6"> --></p>
<p id="p0017" num="0017">In accordance with a preferred embodiment of the invention, the PCA 14 does not delay transmittal of most packets, even of files that require inspection. Rather, while transmitting all but typically the last packet in a file, it operates content inspector software 22 to inspect the contents of the file. If the contents are found to be acceptable, typically the last packet is released. If the contents of a file are not found to be acceptable by the criteria typically established by the policy manager software 20, at least one packet, typically the last packet, is not released, preventing activation of the unacceptable content by the computer.</p>
<p id="p0018" num="0018">Reference is now made to Fig. 1B, which illustrates implementation of the invention for checking all incoming communications along a network 28. In this illustrated embodiment, as seen in Fig. 1B, there is provided a typical computer 30 on which resides TCP/IP software 32. In accordance with a preferred embodiment of the present invention, a packet collection agent (PCA) 34 is interposed between a network interface card (NIC) 36, which receives Internet and intranet traffic, and the TCP/IP software 32.</p>
<p id="p0019" num="0019">In accordance with a preferred embodiment of the present invention, as in the embodiment of Fig. 1A, the PCA 34 interfaces with policy manager software 40, which determines collection criteria, i.e. which types of packets of which types of files are collected, and inspection criteria, i.e. which types of content in a file are not allowed to pass to the computer.</p>
<p id="p0020" num="0020">Based on the criteria typically established by the policy manager software 40, the PCA 34 operates content inspector software 42, which inspects the packets of a file which fits the criteria for collection and inspection. The content inspector software 42 operates typically based on criteria established by the policy manager software 40 and reports its inspection findings to the PCA 34.</p>
<p id="p0021" num="0021">In accordance with a preferred embodiment of the invention, the PCA 34 does not delay transmittal of most packets, even of files that require inspection. Rather while transmitting all but typically the last packet in a file, it operates content inspector software 42 to inspect the contents of the file. If the contents are found to be acceptable, typically the last<!-- EPO <DP n="7"> --> packet is released. If the contents of a file are not found to be acceptable by the criteria typically established by the policy manager software 40, at least one packet, typically the last packet, is not released, preventing activation of the unacceptable content by the computer.</p>
<p id="p0022" num="0022">Reference is now made to Fig. 2, which is a simplified block diagram illustration of the use of multiple content inspectors by a single packet collection agent. As illustrated in Fig. 2, a single PCA 50 may interface with a single policy manager 52, which may, in certain embodiments be obviated, and with a plurality of content inspectors 54 simultaneously. This type of arrangement may be particularly useful for handling high traffic volumes.</p>
<p id="p0023" num="0023">Reference is now made to Fig. 3, which is a simplified flow chart illustrating operation of a PCA in accordance with a preferred embodiment of the present invention.</p>
<p id="p0024" num="0024">As seen in Fig. 3, upon receipt of a packet, if the packet is received in the context of an existing file and is not the last packet, the packet is simultaneously stored and released to its destination, generally in real time.</p>
<p id="p0025" num="0025">If the packet is the last packet in a file, the PCA typically obtains the inspection criteria from the policy manager and sends all of the packets in the file to a content inspector for inspection in accordance with the inspection policy typically established by the policy manager. If the file passes inspection, the last packet is released as well. If not, the last packet is not released.</p>
<p id="p0026" num="0026">If the packet is the first packet of a new file and thus is a control packet as opposed to a data packet, the PCA employs the collection criteria typically established by the policy manager to determine whether the file requires inspection. If not, the packet and all subsequent packets of that file are immediately released as they arrive. If the file is a type of file that is not permitted, no packets are released. If, however, the file is a type of file that requires inspection, the packet is immediately released and the subsequent packets are inspected.</p>
<p id="p0027" num="0027">It will be appreciated by persons skilled in the art that the present invention is<!-- EPO <DP n="8"> --> not limited by what has been particularly shown and described herein above.</p>
<p id="p0028" num="0028">Where technical features mentioned in any claim are followed by reference signs, those reference signs have been included for the sole purpose of increasing the intelligibility of the claims and accordingly, such reference signs do not have any limiting effect on the scope of each element identified by way of example by such reference signs.</p>
</description><!-- EPO <DP n="9"> -->
<claims id="claims01" lang="en">
<claim id="c-en-01-0001" num="0001">
<claim-text>A gateway (10) comprising an input for receiving communications packets, <b>characterized in that</b> it comprises:
<claim-text>an output for outputting communications packetsupon receipt thereof;</claim-text>
<claim-text>a policy manager for (20) determining criteria for the collection of packets and critera for the inspection of the collection of packets, said collection criteria being packet types to be collected of selected file types, and said inspection criteria being content to be inspected;</claim-text>
<claim-text>a packet collection agent (14) receiving packets from said input in accordance with criteria established by said policy manager (20); and</claim-text>
<claim-text>at least one content inspector (22) operated by the packet collection agent (14) and inspecting said collection of packets in accordance with said criteria,</claim-text>
<claim-text>said packet collection agent (14) being operative to prevent supply of at least one packet but not all packets of said collection of packets to said output when said collection of packets includes undesirable content in accordance with said criteria.</claim-text></claim-text></claim>
<claim id="c-en-01-0002" num="0002">
<claim-text>A gateway according to claim 1 and wherein said at least one packet is the last packet of a file.</claim-text></claim>
<claim id="c-en-01-0003" num="0003">
<claim-text>A gateway according to any of claims 1 to 2 and wherein said packet collection agent (14) inspects all packets of files that are to be inspected.</claim-text></claim>
<claim id="c-en-01-0004" num="0004">
<claim-text>A gateway according to any of claims 1 to 3 and wherein said at least one content inspector (22) includes a plurality of content inspectors (54) simultaneously inspecting said collection of packets.</claim-text></claim>
<claim id="c-en-01-0005" num="0005">
<claim-text>A gateway according to any of claims 1 to 4 and wherein said policy manager (20) determines criteria whereby released of packets of some types of files is prevented by the packet collection agent.<!-- EPO <DP n="10"> --></claim-text></claim>
<claim id="c-en-01-0006" num="0006">
<claim-text>A gateway according to any of claims 1 to 5 and wherein said packet collection agentoperates on Internet but not on intranst traffic.</claim-text></claim>
<claim id="c-en-01-0007" num="0007">
<claim-text>A method for protecting a computer from malicious content comprising: the steps of:
<claim-text>at a gateway, determining criteria for the collection of packets and critera for the inspection of the collection of packets, said collection criteria being packet types to be collected of selected file types, and said inspection criteria being content to be inspected;</claim-text>
<claim-text>receiving packets from among the collection of packets in accordance with the criteria;</claim-text>
<claim-text>inspecting the packets in accordance with the criteria;</claim-text>
<claim-text>preventing output of at least one packet but not all packets of said collection of packets when the collection of packets includes undesirable content in accordance with the criteria; and</claim-text>
<claim-text>outputting packets other than the at least one packet upon receipt thereof.</claim-text></claim-text></claim>
<claim id="c-en-01-0008" num="0008">
<claim-text>A method according to claim 7 and wherein said at least one packet is the last packet of a file.</claim-text></claim>
<claim id="c-en-01-0009" num="0009">
<claim-text>A method according to claim 7 and wherein said inspecting includes inspecting all packets of files that are to be inspected.</claim-text></claim>
<claim id="c-en-01-0010" num="0010">
<claim-text>A method according to claim 7 and wherein said inspecting includes inspecting by a plurality of content inspectors simultaneously.</claim-text></claim>
<claim id="c-en-01-0011" num="0011">
<claim-text>A method according to claim 7 and wherein said determining criteria includes determining criteria whereby packets of some types of files are prevented from being released.</claim-text></claim>
<claim id="c-en-01-0012" num="0012">
<claim-text>A method according to claim 7 and wherein a packet collection agent operates on Internet but not on intranet traffic.</claim-text></claim>
</claims><!-- EPO <DP n="11"> -->
<claims id="claims02" lang="de">
<claim id="c-de-01-0001" num="0001">
<claim-text>Ein Gateway (10), das eine Eingabe zum Empfangen von Nachrichtenpaketen umfasst, <b>dadurch gekennzeichnet, dass</b> es folgendes umfasst:
<claim-text>eine Ausgabe zum Ausgeben von Nachrichtenpaketen bei ihrem Empfang;</claim-text>
<claim-text>einen Vorgehensweise-Verwalter (20) zum Bestimmen von Kriterien für die Sammlung von Paketen und von Kriterien für die Untersuchung der Sammlung von Paketen, wobei die Sammelkriterien zu sammelnde Pakettypen ausgewählter Dateitypen sind und wobei die Untersuchungskriterien der zu untersuchende Inhalt sind;</claim-text>
<claim-text>einen Paketsammelagenten (14), der in Übereinstimmung mit vom Vorgehensweise-Verwalter (20) festgelegten Kriterien Pakete von der Eingabe empfängt; und</claim-text>
<claim-text>mindestens einen vom Paketsammelagenten (14) betriebenen Inhaltsinspektor (22), der die Sammlung von Paketen in Übereinstimmung mit den Kriterien untersucht,</claim-text>
<claim-text>wobei der Paketsammelagent (14) wirksam ist, um die Zufuhr von mindestens einem Paket, aber nicht aller Pakete, aus der Sammlung von Paketen an die Ausgabe zu verhindern, wenn die Sammlung von Paketen in Übereinstimmung mit den Kriterien einen unerwünschten Inhalt einschließt.</claim-text></claim-text></claim>
<claim id="c-de-01-0002" num="0002">
<claim-text>Ein Gateway nach Anspruch 1, und worin das mindestens eine Paket das letzte Paket einer Datei ist.</claim-text></claim>
<claim id="c-de-01-0003" num="0003">
<claim-text>Ein Gateway nach irgendeinem der Ansprüche 1 bis 2, und worin der Paketsammelagent (14) alle Pakete der Dateien untersucht, die untersucht werden sollen.</claim-text></claim>
<claim id="c-de-01-0004" num="0004">
<claim-text>Ein Gateway nach irgendeinem der Ansprüche 1 bis 3, und worin der mindestens eine Inhaltsinspektor (22) mehrere Inhaltsinspektoren (54) einschließt, die gleichzeitig die Sammlung von Paketen untersuchen.</claim-text></claim>
<claim id="c-de-01-0005" num="0005">
<claim-text>Ein Gateway nach irgendeinem der Ansprüche 1 bis 4, und<!-- EPO <DP n="12"> --> worin der Vorgehensweise-Verwalter (20) Kriterien bestimmt, durch die die Freigabe von Paketen von einigen Dateitypen von den Paketsammelagenten verhindert wird.</claim-text></claim>
<claim id="c-de-01-0006" num="0006">
<claim-text>Ein Gateway nach irgendeinem der Ansprüche 1 bis 5, und worin der Paketsammelagent im Internet-, aber nicht im IntranetVerkehr, arbeitet.</claim-text></claim>
<claim id="c-de-01-0007" num="0007">
<claim-text>Ein Verfahren zum Schützen eines Computers vor einem böswilligen Inhalt schützt, das folgende Schritte umfasst:
<claim-text>das Bestimmen an einem Gateway von Kriterien für die Sammlung von Paketen und Kriterien für die Untersuchung der Sammlung von Paketen, wobei die Sammelkriterien zu sammelnde Pakettypen ausgewählter Dateitypen sind und wobei die Untersuchungskriterien den zu untersuchenden Inhalt darstellen;</claim-text>
<claim-text>das Empfangen von Paketen aus der Sammlung von Paketen in Übereinstimmung mit den Kriterien;</claim-text>
<claim-text>das Untersuchen der Pakete in Übereinstimmung mit den Kriterien;</claim-text>
<claim-text>das Verhindern der Ausgabe von mindestens einem Paket, aber nicht von allen Paketen aus der Sammlung von Paketen, wenn die Sammlung von Paketen in Übereinstimmung mit den Kriterien einen unerwünschten Inhalt einschließt; und</claim-text>
<claim-text>das Ausgeben von Paketen, die nicht das mindestens eine Paket sind, bei ihrem Empfang.</claim-text></claim-text></claim>
<claim id="c-de-01-0008" num="0008">
<claim-text>Ein Verfahren nach Anspruch 7, und worin das mindestens eine Paket das letzte Paket einer Datei ist.</claim-text></claim>
<claim id="c-de-01-0009" num="0009">
<claim-text>Ein Verfahren nach Anspruch 7, und worin die Untersuchung das Untersuchen aller Dateienpakete einschließt, die untersucht werden sollen.</claim-text></claim>
<claim id="c-de-01-0010" num="0010">
<claim-text>Ein Verfahren nach Anspruch 7, und worin die Untersuchung das gleichzeitige Untersuchen durch mehrere Inhaltsinspektoren einschließt.<!-- EPO <DP n="13"> --></claim-text></claim>
<claim id="c-de-01-0011" num="0011">
<claim-text>Ein Verfahren nach Anspruch 7, und worin die Bestimmungskriterien Bestimmungskriterien einschließen, durch die verhindert wird, dass die Pakete einiger Dateitypen freigegeben werden.</claim-text></claim>
<claim id="c-de-01-0012" num="0012">
<claim-text>Ein Verfahren nach Anspruch 7, und worin ein Paketsammelagent im Internet-, aber nicht im Intranetverkehr arbeitet.</claim-text></claim>
</claims><!-- EPO <DP n="14"> -->
<claims id="claims03" lang="fr">
<claim id="c-fr-01-0001" num="0001">
<claim-text>Passerelle (10) comprenant une entrée pour recevoir des paquets de communication, <b>caractérisée en ce qu'</b>elle comprend :
<claim-text>une sortie pour émettre des paquets de communication à réception de ceux-ci ;</claim-text>
<claim-text>un gestionnaire de règles (20) pour déterminer des critères pour la collecte de paquets et des critères pour l'inspection de la collecte de paquets, lesdits critères de collecte étant des types de paquets devant être collectés de types de fichiers sélectionnés, et lesdits critères d'inspection étant le contenu devant être inspecté ;</claim-text>
<claim-text>un agent de collecte de paquets (14) recevant les paquets depuis ladite entrée selon les critères établis par ledit gestionnaire de règles (20) ; et</claim-text>
<claim-text>au moins un inspecteur de contenu (22) opéré par l'agent de collecte de paquets (14) et inspectant ladite collecte de paquets selon lesdits critères,</claim-text>
<claim-text>ledit agent de collecte de paquets (14) étant opérationnel pour empêcher la fourniture d'au moins un paquet, mais pas tous les paquets, de ladite collecte de paquets à ladite sortie, lorsque ladite collecte de paquets comprend un contenu indésirable selon lesdits critères.</claim-text></claim-text></claim>
<claim id="c-fr-01-0002" num="0002">
<claim-text>Passerelle selon la revendication 1 et dans laquelle ledit au moins un paquet est le dernier paquet d'un fichier.<!-- EPO <DP n="15"> --></claim-text></claim>
<claim id="c-fr-01-0003" num="0003">
<claim-text>Passerelle selon l'une quelconque des revendications 1 à 2, et dans laquelle ledit agent de collecte de paquet (14) inspecte tous les paquets de fichiers qui doivent être inspectés.</claim-text></claim>
<claim id="c-fr-01-0004" num="0004">
<claim-text>Passerelle selon l'une quelconque des revendications 1 à 3, et dans laquelle ledit au moins un inspecteur de contenu (22) comprend une pluralité d'inspecteurs de contenu (54) inspectant simultanément ladite collecte de paquets.</claim-text></claim>
<claim id="c-fr-01-0005" num="0005">
<claim-text>Passerelle selon l'une quelconque des revendications 1 à 4, et dans laquelle ledit gestionnaire de règles (20) détermine des critères, de sorte que la libération de paquets de certains types de fichiers est entravée par l'àgent de collecte de paquets.</claim-text></claim>
<claim id="c-fr-01-0006" num="0006">
<claim-text>Passerelle selon l'une quelconque des revendications 1 à 5, et dans laquelle ledit agent de collecte de paquets opère sur Internet mais pas sur un réseau Intranet.</claim-text></claim>
<claim id="c-fr-01-0007" num="0007">
<claim-text>Procédé de protection d'un ordinateur contre des contenus malveillants comprenant les étapes suivantes :
<claim-text>au niveau d'une passerelle, la détermination des critères pour la collecte des paquets et des critères pour l'inspection de la collecte de paquets, lesdits critères de collecte étant des types de paquets devant être collectés de types de fichiers sélectionnés, et lesdits critères d'inspection étant le contenu devant être inspecté ;</claim-text>
<claim-text>la réception de paquets provenant de la collecte de paquets selon les critères<!-- EPO <DP n="16"> --></claim-text>
<claim-text>l'inspection des paquets selon-les critères ;</claim-text>
<claim-text>le blocage de la sortie d'au moins un paquet, mais pas tous les paquets, de ladite collecte de paquets, lorsque la collecte de paquets comprend un contenu indésirable selon les critères ; et</claim-text>
<claim-text>l'émission de paquets autres que le au moins un paquet à réception de ceux-ci.</claim-text></claim-text></claim>
<claim id="c-fr-01-0008" num="0008">
<claim-text>Procédé selon la revendication 7 et dans lequel ledit au moins un paquet est le dernier paquet d'un fichier.</claim-text></claim>
<claim id="c-fr-01-0009" num="0009">
<claim-text>Procédé selon la revendication 7 et dans lequel ladite inspection comprend l'inspection de tous les paquets de fichiers qui doivent être inspectés.</claim-text></claim>
<claim id="c-fr-01-0010" num="0010">
<claim-text>Procédé selon la revendication 7 et dans lequel ladite inspection comprend l'inspection par une pluralité d'inspecteurs de contenu simultanément.</claim-text></claim>
<claim id="c-fr-01-0011" num="0011">
<claim-text>Procédé selon la revendication 7 et dans lequel ladite détermination des critères comprend la détermination des critères, de sorte que la libération des paquets de certains types de fichiers est entravée.</claim-text></claim>
<claim id="c-fr-01-0012" num="0012">
<claim-text>Procédé selon la revendication 7 et dans lequel un agent de collecte de paquets opère sur Internet, mais pas sur un réseau Intranet.</claim-text></claim>
</claims><!-- EPO <DP n="17"> -->
<drawings id="draw" lang="en">
<figure id="f0001" num=""><img id="if0001" file="imgf0001.tif" wi="163" he="233" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="18"> -->
<figure id="f0002" num=""><img id="if0002" file="imgf0002.tif" wi="165" he="220" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="19"> -->
<figure id="f0003" num=""><img id="if0003" file="imgf0003.tif" wi="165" he="198" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="20"> -->
<figure id="f0004" num=""><img id="if0004" file="imgf0004.tif" wi="161" he="233" img-content="drawing" img-format="tif"/></figure>
</drawings>
</ep-patent-document>
